CWE-300Class

Channel Accessible by Non-Endpoint

Draft in the CWE catalog · 49 CVEs mapped

49
CVEs mapped
6.5
Median CVSS
What it is

The product does not adequately verify the identity of actors at both ends of a communication channel, or does not adequately ensure the integrity of the channel, in a way that allows the channel to be accessed or influenced by an actor that is not an endpoint.

Recent examples
9.8cvss
CVE-2026-74232

CVE-2026-74232 - CRITICAL Severity Vulnerability

Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.1101, Zbtlink ZBT-7628 firmware 1.0.0.2.007, Zbtlink ZBT-ZBT7621 firmware 1.0.0.3.001, MoreQuick MQAC-7620, MQAC-7620A, MQAP-7620, MQAP-7620A, and MQAP-7628 firmware 1.0.0.2.000, AP522 firmware 1.0.0.2.014, AP7628 and HC5661A firmware 3.0.0.4.380, APG721B firmware 19.0809, HK300 firmware 1.0.0.2.032, and MAP-N10 firmware 1.0.0.2.044 ship a backdoor command-and-control implant (yunmgrd) reachable over an unauthenticated cleartext UDP channel to a hardcoded C2 server. A remote unauthenticated attacker on the network path can hijack the channel and execute arbitrary commands as root. The attacker can also modify DNS entries, exfiltrate PPPoE credentials, and open reverse SSH tunnels.

CRITICALno explanation yet
0%
epss
7.1cvss
CVE-2025-29419

CVE-2025-29419 - HIGH Severity Vulnerability

CTFd v3.7.6 was discovered to be vulnerable to a man-in-the-middle attack.

HIGHno explanation yet
0%
epss
8.7cvss
CVE-2026-12991

Multiple vulnerabilities in Ghost Robotics' Vision 60

The lack of cryptographic mechanisms to ensure the integrity and authenticity of communications in Ghost Robotics' Vision 60 robot (APK v5.5.0) exposes the system to man-in-the-middle attacks. An attacker located on the local network can use ARP spoofing and selective traffic blocking techniques to intercept and manipulate packets between the legitimate operator and the robot. This allows the attacker to disconnect the original controller, establish unauthorized communications, and prevent the operator from regaining control of the device, seriously compromising the confidentiality, integrity, and availability (CIA) of operations.

HIGHno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-300
Abstraction
Class
Structure
Simple
Status
Draft